The stable version and lack of install-time scripts reduce integration risk. Repository documentation and project safeguards provide little evidence for ongoing support.
38%
Total Score
69
67
The package has made only two releases, both in June 2020, with no releases in the last six years. This is strong evidence of abandonment risk despite the stable version.
No license is declared, detected, or included in the package or repository. That creates a material adoption and redistribution risk with no compensating license evidence.
The published artifact contains only three files, and the repository contains only four, including a documentation README. This unusually small footprint may be intentional, but provides little visible project context or validation evidence.
The package contains no README, tests, or changelog, while the repository has no tests or changelog either. The missing consumer documentation and lack of project validation reduce transparency and maintenance confidence.
Composer is used as the build tool, which is appropriate for a Packagist package, but no security scanning tooling is present. The missing scanning is a moderate hygiene gap rather than proof of unsafe code.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.